Distributed OCSP Pre-computation for Certificate Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional OCSP systems face challenges such as computational intensity, network bottlenecks, security vulnerabilities, and scalability issues due to the need for secure vaults and centralized key management, particularly in handling large volumes of digital certificate validity queries across multiple organizations.

Innovation Solution

A distributed system that pre-computes and digitally signs the validity status of digital certificates, allowing for efficient OCSP format responses to be generated and cached, reducing the computational load on responders and eliminating the need for secure vaults by using a single dedicated server for digital signatures, while enabling secure and scalable credential validation across multiple organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional OCSP systems use centralized key management with secure vaults, then security is improved, but device complexity and operational costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidvault infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the OCSP system into multiple distributed responders, each maintaining its own copy of certificate status information. This segmentation eliminates the need for a centralized secure vault while maintaining security through distributed key management. Each responder independently manages its cryptographic keys, removing the single point of failure and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements replication of certificate status information across multiple distributed responders. Instead of relying on a single centralized database protected by a vault, the system creates and maintains copies of the same information across multiple nodes. This copying approach provides redundancy and eliminates the need for expensive secure vault infrastructure while maintaining data availability and security.

Inventive Principle:
Principle #26Copying

2Device complexity

If a single centralized OCSP responder handles all certificate validity queries, then security is simplified, but network bottlenecks and scalability issues occur

Engineering Contradiction:
Improvekey managementVSAvoidquery handling capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the centralized OCSP responder into multiple distributed responders that share the query handling load. Each responder handles a portion of the certificate validity queries independently, eliminating the network bottleneck that would occur with a single centralized system. This segmentation maintains simplified key management at each local node while dramatically improving overall query handling capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-point centralized architecture to a distributed architecture that utilizes network redundancy and geographic distribution. By adding the dimension of distribution across multiple nodes, the system maintains simplified local key management while scaling query handling capacity through parallel processing across the distributed network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If OCSP responders generate digital signatures for each certificate status query in real-time, then response freshness is improved, but computational intensity increases

Engineering Contradiction:
Improveresponse freshnessVSAvoidcomputational load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements pre-computation of certificate status information and digital signatures by distributed responders. Instead of generating signatures in real-time for each query, the responders pre-compute and cache status information along with corresponding digital signatures. This preliminary action reduces the computational load during actual query processing while maintaining response freshness through periodic updates of the pre-computed data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs periodic updates of pre-computed certificate status information and digital signatures across distributed responders. Rather than continuous real-time signature generation, the system performs periodic batches of pre-computation and then serves cached results for multiple queries. This periodic action maintains sufficient freshness for security purposes while dramatically reducing instantaneous computational intensity.

Inventive Principle:
Principle #19Periodic action

4Measurement precision

If CRL contains all revoked certificates to provide comprehensive revocation information, then validation accuracy is improved, but data size and transmission cost increase

Engineering Contradiction:
Improvevalidation accuracyVSAvoiddata size
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent implements localized certificate status information storage at each distributed responder. Instead of maintaining a comprehensive global CRL that includes all revoked certificates across the entire certificate hierarchy, each responder stores only the revocation information relevant to its local scope. This local quality approach provides sufficient validation accuracy for local certificate verification while dramatically reducing data size and transmission requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the comprehensive CRL into distributed, localized revocation information stored at multiple responders. Rather than transmitting and storing a single large global CRL containing all revoked certificates, the system divides the revocation data into smaller segments maintained at distributed nodes. This segmentation maintains validation accuracy for local certificates while reducing overall data quantity and transmission costs.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7966487B2Communication-efficient real time credentials for OCSP and distributed OCSP
Publication Date: 2011.06.21 ASSA ABLOY AB
  • US7966487B2 patent drawing
  • US7966487B2 patent drawing
  • US7966487B2 patent drawing

AI summary

Facilitating a transaction between a first party and a second party includes, prior to initiating the transaction, one of the parties obtaining an artificially pre-computed OCSP response about a specific digital certificate, where the artificially pre-computed OCSP response is generated by an entity other than the first party and the second party, one of the parties initiating the transaction, in connection with the transaction, the first party providing the specific digital certificate to the second party, and the second party verifying the specific digital certificate using the artificially pre-computed OCSP response. The second party may obtain the artificially pre-computed OCSP response prior to the transaction being initiated. The second party may cache the artificially pre-computed OCSP response for future transactions. The first party may obtain the artificially pre-computed OCSP response prior to the transaction being initiated. The first party may cache the artificially pre-computed OCSP response for future transactions.